<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Gitea</title><description>Vulnerabilities and advisories affecting Gitea, the self-hosted Git service, including its official Docker images. Combined article + CVE feed for the Gitea beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CISA: Gitea RCE Now Exploited, Miner Payloads Confirmed</title><link>https://0daynews.com/articles/2026-08-26-gitea-rce-kev-active-exploitation-cryptominer/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-26-gitea-rce-kev-active-exploitation-cryptominer/</guid><description>CISA has added a critical Gitea code injection flaw to the KEV catalog as attackers drop cryptominer-like payloads on unpatched self-hosted instances. Patch to version 1.27.1 now.</description><pubDate>Wed, 26 Aug 2026 08:15:00 GMT</pubDate><category>Gitea</category><category>article</category></item><item><title>CVE-2026-20896 — Gitea Docker image ships permissive reverse-proxy trusted list, allowing header-based auth bypass</title><link>https://0daynews.com/cve/cve-2026-20896/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20896/</guid><description>The Gitea Docker image up through 1.26.2 shipped with the reverse-proxy trusted-proxy list set to a wildcard, letting an unauthenticated request that sets an X-WEBAUTH-USER header authenticate as an arbitrary account. Reported by Ali Mustafa (@rz1027) in early June 2026, fixed in Gitea 1.26.3. CVSS 9.8. The Hacker News reported opportunistic scanning against exposed instances on 2026-07-06, 13 days after disclosure; roughly 6,200 internet-facing Gitea instances remained exposed at the time.</description><pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate><category>Gitea</category><category>critical</category><category>cve</category></item><item><title>Gitea Patches Critical RCE, Upgrade to 1.27.1</title><link>https://0daynews.com/articles/2026-07-29-gitea-critical-rce-git-hook-1-27-1/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-gitea-critical-rce-git-hook-1-27-1/</guid><description>A critical RCE in Gitea lets any repository writer plant a git hook via patch content and run shell commands as the service account. Upgrade to 1.27.1 now.</description><pubDate>Wed, 29 Jul 2026 11:00:00 GMT</pubDate><category>Gitea</category><category>article</category></item><item><title>Gitea Docker Auth Bypass: Patch 1.26.4, CSA Confirms</title><link>https://0daynews.com/articles/2026-07-11-gitea-docker-cve-2026-20896-sysdig-csa-1264-regression/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-11-gitea-docker-cve-2026-20896-sysdig-csa-1264-regression/</guid><description>Sysdig confirms the first in-the-wild hit on Gitea Docker CVE-2026-20896; Singapore CSA now warns customers; 1.26.3 shipped with a regression, so run 1.26.4.</description><pubDate>Sat, 11 Jul 2026 12:03:16 GMT</pubDate><category>Gitea</category><category>article</category></item><item><title>Gitea Docker&apos;s Auth Bypass: Probing Already Underway</title><link>https://0daynews.com/articles/2026-07-06-gitea-docker-cve-2026-20896-header-auth-bypass/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-06-gitea-docker-cve-2026-20896-header-auth-bypass/</guid><description>The Gitea Docker image up through 1.26.2 shipped a wildcard reverse-proxy trusted list, collapsing auth to a header. Fixed in 1.26.3. The Hacker News reports opportunistic scanning 13 days after disclosure; ~6,200 exposed instances.</description><pubDate>Mon, 06 Jul 2026 18:20:00 GMT</pubDate><category>Gitea</category><category>article</category></item></channel></rss>